Falhas do tipo CWE-20

5.444 resultados

Validação inadequada de entrada

A aplicação recebe dados do usuário ou de fontes externas mas não valida (ou valida mal) se esses dados têm as propriedades necessárias para processamento seguro. Isso abre porta para injeção de código, buffer overflow, lógica corrompida e outros ataques que exploram dados malformados ou maliciosos.

Exemplo

Um formulário web aceita um CPF sem verificar se tem 11 dígitos numéricos, ou um app móvel recebe um ID de usuário em JSON sem confirmar se é um inteiro — atacantes exploram isso para acessar dados de outros usuários, executar queries SQL maliciosas ou causar erro de processamento.

Como mitigar

Implemente validação rigorosa na entrada: verifique tipo, comprimento, formato, intervalo de valores permitidos. Use whitelist (aceitar só o que você sabe ser seguro) em vez de blacklist. Valide tanto no cliente quanto no servidor, e use bibliotecas de parsing seguro para formatos complexos (XML, JSON).

CVE-2026-13699MEDIUMDatabroker 0.6.1 PublishValue missing data_point panicEPSS 0.4%CVE-2024-4027HIGHUndertow: outofmemoryerror in httpservletrequestimpl.getparameternames() can cause remote dos attacksEPSS 0.4%CVE-2026-17664MEDIUMInsufficient validation of untrusted input in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised tEPSS 0.4%CVE-2022-47909MEDIUMLQL Injection in Livestatus HTTP headersEPSS 0.4%CVE-2026-45628CRITICALDokploy: Command Injection via Unescaped Branch Fields in Deployment PipelineEPSS 0.4%CVE-2026-48774HIGHProxySQL MCP run_sql_readonly executes side-effecting MySQL multi-statements despite read-only contractEPSS 0.4%CVE-2026-79410HIGHImproper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce theiEPSS 0.4%CVE-2025-60537MEDIUMImproper input validation in the component /kafka/ui/serdes/CustomSerdeLoader.java of kafka-ui v0.6.0 to v0.7.2 allows attackers to execute EPSS 0.4%CVE-2026-9211MEDIUMCertain NETGEAR routers allow unauthenticated users to gain control of the routerEPSS 0.4%CVE-2025-61235CRITICALAn issue was discovered in Dataphone A920 v2025.07.161103. A custom packet based on public documentation can be crafted, where some fields cEPSS 0.4%CVE-2026-4519HIGHwebbrowser.open() allows leading dashes in URLsEPSS 0.4%CVE-2017-14025—An Improper Input Validation issue was discovered in ABB FOX515T release 1.0. An improper input validation vulnerability has been identifiedEPSS 0.4%CVE-2025-32077MEDIUMXSSes in Extension:SimpleCalendarEPSS 0.4%CVE-2026-50569MEDIUMFission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checksEPSS 0.4%CVE-2026-52780CRITICALOpenProject: Cache store poisoning leads to Remote Code Execution (RCE)EPSS 0.4%CVE-2026-65604HIGHSkipper Incomplete Fix for CVE-2026-50197 Policy BypassEPSS 0.4%CVE-2025-24319HIGHBIG-IP Next Central Manager vulnerabilityEPSS 0.4%CVE-2018-15368—Cisco IOS XE Software Privileged EXEC Mode Root Shell Access VulnerabilityEPSS 0.4%CVE-2025-50494HIGHImproper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackersEPSS 0.4%CVE-2026-95659MEDIUMMISP Reflected XSS via Unvalidated Object Type in AnalystData Overmind ThreadEPSS 0.4%